On Oct. 1, 2020, the U.S. Treasury’s Office of Foreign Assets Control issued an advisory on the sanctions risk of facilitating ransomware payments. It stated that companies that make or arrange payments on behalf of victims, including financial institutions, cyber insurance firms and digital forensics and incident response companies, may be violating OFAC regulations if the recipient is a sanctioned person or entity. The Financial Crimes Enforcement Network issued a companion advisory the same day.
The advisory listed the ransomware actors already under sanctions: Evgeniy Bogachev of CryptoLocker, two Iranian nationals tied to SamSam, the Lazarus Group behind WannaCry and Evil Corp, sanctioned in December 2019 for Dridex. It reminded readers that civil liability under the sanctions regime is strict. A payer does not need to know the recipient is sanctioned to be liable.
The Insurer Was Named On Purpose
By 2020, a ransomware payment was rarely a victim acting alone. The insurer approved it, a negotiator handled it and a forensics firm certified the decryptor. The advisory addressed that chain directly. An insurer reimbursing a payment to Evil Corp, whose Phoenix locker would hit CNA Financial six months later, filed at 21-0323, was now on notice that the reimbursement itself carried exposure.
What It Did And Did Not Do
The document imposed no penalty and created no new rule. It named mitigating factors: a risk-based compliance program, and reporting the attack to law enforcement promptly and completely. The updated version of Sept. 21, 2021, strengthened the language discouraging payment and was issued alongside the designation of SUEX, a virtual currency exchange, the first such designation over ransomware proceeds.
The practical effect was procedural. Insurers and negotiators began screening attacker wallets and personas against the sanctions list before any payment, and declining where a match or a plausible link appeared. The corpus later recorded a $22 million payment at 24-0301 and a $75 million payment at 25-0728. Neither went to a sanctioned actor, and the screening that establishes that is the advisory’s legacy.
Compiled from the OFAC advisory and its 2021 update, the Treasury press release on the SUEX designation and the CISA alert summarising the advisory, listed below. The advisory is guidance; no enforcement action against an insurer under it was found. Graded high. Corrections: corrections@forensicpost.com.